could not find an available, non-overlapping IPv4 address pool among the defaults
Fixes docker network creation failing with 'could not find an available, non-overlapping IPv4 address pool'. Use when the daemon has exhausted its default subnet ranges, common on hosts with many networks or VPNs squatting the ranges. Not for explicit subnet overlaps you configured yourself.
TL;DR: The daemon is out of default subnets to hand out. Free unused networks with docker network prune, or define a custom address pool in /etc/docker/daemon.json under default-address-pools. Corporate VPNs and lots of compose projects eat the defaults fast.
The error
could not find an available, non-overlapping IPv4 address pool among the defaults to assign to the networkFix it
- See how many networks exist:
docker network ls | wc -l Expected: a large number, or a few plus VPN interfaces squatting 172.x ranges.
- Prune the unused ones:
docker network prune Expected: removes unused networks; confirm with docker network ls.
- Retry creating your network. If it still fails, add custom pools to /etc/docker/daemon.json:
{"default-address-pools": [{"base": "CONTAINER_IP/16", "size": 24}]}
- Restart the daemon and retry:
sudo systemctl restart docker Expected: new networks get subnets from your custom pool.
When this applies
- Hosts with dozens of docker networks or VPN clients occupying 172.16-31.x
- CI machines that create networks per job without cleanup
When this does NOT apply
- "Pool overlaps with other one on this address space" (you picked a specific conflicting subnet; different fix)
- Single network failing while plenty of room exists (check the daemon.json syntax)
Versions
Docker Engine 18.06+ (default-address-pools exists since then).
Why it happens
The daemon hands out /16 chunks from 172.17-31.x and 192.168.x for new bridge networks. Each network consumes one chunk, and anything else on the host using those ranges (VPNs, other VMs) shrinks the available set. When nothing fits, creation fails with this error.
Edge cases
- daemon.json must be valid JSON; a trailing comma prevents the daemon from starting at all. Validate with
python3 -m json.tool /etc/docker/daemon.json. - The
sizemust be smaller than the base prefix (e.g. /24 subnets from a /16 base). - Existing networks keep their old subnets; the new pools only apply to networks created after the restart.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.